COLDSTEEL RAT Cleanup Command Execution
Detects the creation of a "rundll32" process from the ColdSteel persistence service to initiate the cleanup command by calling one of its own exports. This functionality is not present in "MileStone2017" and some "MileStone2016" samples
Detection logic
selection
ParentImage|endswith: \svchost.exe
ParentCommandLine|contains:
- " -k msupdate"
- " -k msupdate2"
- " -k alg"
Image|endswith: \rundll32.exe
CommandLine|contains:
- UpdateDriverForPlugAndPlayDevicesW
- ServiceMain
- DiUninstallDeviceCondition
selectionRaw YAML
title: COLDSTEEL RAT Cleanup Command Execution
id: 88516f06-ebe0-47ad-858e-ae9fd060ddea
status: test
description: Detects the creation of a "rundll32" process from the ColdSteel persistence service to initiate the cleanup command by calling one of its own exports. This functionality is not present in "MileStone2017" and some "MileStone2016" samples
references:
- https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/cold-steel/NCSC-MAR-Cold-Steel.pdf
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-04-30
tags:
- attack.persistence
- detection.emerging-threats
- attack.stealth
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\svchost.exe'
ParentCommandLine|contains:
- ' -k msupdate'
- ' -k msupdate2'
- ' -k alg'
Image|endswith: '\rundll32.exe'
CommandLine|contains:
- 'UpdateDriverForPlugAndPlayDevicesW'
- 'ServiceMain'
- 'DiUninstallDevice'
condition: selection
falsepositives:
- Unlikely
level: criticalFalse positives
- Unlikely
References
Similar rules
APT27 - Emissary Panda Activity
criticalwindows · Same logsource category (process_creation)
COLDSTEEL RAT Anonymous User Process Execution
highwindows · Same logsource category (process_creation)
COLDSTEEL RAT Service Persistence Execution
criticalwindows · Same logsource category (process_creation)
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
mediumwindows · Same logsource category (process_creation)